Data of Almost 40,000 SafePal Hardware Wallet Users Exposed to Third Parties

cryptonews.ru發佈於 2026-08-17更新於 2026-08-17

文章摘要

Hardware crypto wallet manufacturer SafePal has disclosed a data breach affecting approximately 39,798 users. On August 16, the company announced that leaked information includes customer names, delivery addresses, phone numbers, email addresses, and order details. However, sensitive data such as seed phrases, private keys, passwords, bank details, and card numbers were not compromised, as SafePal states it does not collect or store this information. An internal investigation found no evidence that attackers accessed user wallets or funds. The primary risk for affected customers is targeted social engineering attacks. Scammers may use the leaked order details to pose as customer support, offering fake refunds, urging firmware updates, or sending phishing links. SafePal is monitoring and taking down such fraudulent sites and warns users to be cautious of any communication referencing their order information. The breach originated from an authorization vulnerability in a third-party order-tracking plugin, which allowed unauthorized access to other customers' order data. The issue affected orders placed between March 2, 2025, and April 11, 2026. The company has since patched the vulnerability and strengthened its system protections. In response, SafePal is conducting a joint investigation with an independent security firm and auditing its entire order processing system. Additional measures include reducing data retention in the affected system to 90 days and notifying logisti...

The manufacturer of SafePal hardware crypto wallets has reported a data leak affecting approximately 39,798 users. The company disclosed the incident on August 16, clarifying that third parties gained access to customer names, delivery addresses, phone numbers, email addresses, and order information.

However, seed phrases, private keys, passwords, bank details, card numbers, and document numbers were not affected by the leak—SafePal initially does not collect or store such information. The project team has inspected its systems and found no signs that malicious actors gained access to user wallets or funds.

The Danger of the Leak for Customers

The developers warned: even without access to cryptocurrency assets, the leaked data provides grounds for targeted attacks. Scammers may call or write to customers posing as support staff, offer "refunds," persuade them to update device firmware, or send links to phishing resources impersonating the SafePal website.

The company is already tracking the appearance of such fake resources and working to get them blocked. Customers should be cautious of any communications that mention details of their orders—precisely this information may now be used to make messages appear credible.

Error in Order Tracking Plugin

According to SafePal, the leak occurred due to a vulnerability in the order tracking plugin linked to customer data. An authorization flaw in it allowed an unauthorized user to access orders of other customers—meaning they could see someone else's information where only their own should have been displayed.

By the time of the statement's publication, the developers had already fixed the issue and strengthened system protection measures. The incident affected those who placed orders between March 2, 2025, and April 11, 2026. When exactly the malicious actors exploited the vulnerability and when the project team discovered it was not specified by the company.

What SafePal is Doing Next

The manufacturer is currently investigating the incident in collaboration with an independent security company and preparing an audit of the entire order processing system. Among the measures taken are reducing the data retention period in the affected system to 90 days, notifying logistics partners with a request to check if the issue impacted their own systems, fixing the vulnerability in the plugin, and strengthening access controls to customer data.

Thus, the leak did not jeopardize the cryptocurrency assets of SafePal users, but it exposed enough personal data to organize fraudulent schemes through social engineering. The company states that it will continue to monitor the situation and investigate together with external security experts.

AI Opinion

Analysis reveals a clear industry pattern: the SafePal incident is already the third case of customer contact data leakage from hardware wallet manufacturers in recent years, and each time malicious actors use the same scheme—phishing emails sent impersonating support. A similar story happened with Ledger in 2020 when data of a million customers leaked, and victims were then pursued by fraudulent mailings for months, including fake devices by mail. Trezor faced the same problem very recently.

A technical aspect left outside the article's scope: the vulnerability arose not in the hardware wallet itself, but in a third-party order tracking plugin—this points to a weak link not in the devices' cryptography, but in auxiliary web services that companies connect to their platforms. Moreover, the leak's timeframe—over a year—raises questions: how many more such vulnerabilities in manufacturers' adjacent systems remain unnoticed until the data starts being used against the customers themselves?

熱門幣種推薦

相關問答

QAccording to the article, what type of user data was leaked in the SafePal incident?

AThe leaked data included customer names, delivery addresses, phone numbers, email addresses, and order details. However, sensitive information like seed phrases, private keys, passwords, bank details, card numbers, and identification documents was not compromised, as SafePal does not collect or store such data.

QWhat is the primary security risk for SafePal customers following this data leak, as mentioned in the article?

AThe primary risk is targeted attacks using social engineering. Scammers can use the leaked personal and order information to impersonate SafePal support, call or message customers, offer 'refunds,' convince them to update device firmware, or send phishing links to fake websites, making their schemes appear more legitimate.

QWhat was identified as the specific cause of the data breach at SafePal?

AThe breach was caused by a vulnerability in an order tracking plugin. An authorization error in this plugin allowed unauthorized users to access the orders and personal information of other customers, seeing data that should only have been visible to the account owner.

QWhat period of time did the SafePal data breach affect, and what key actions did the company take in response?

AThe breach affected customers who placed orders between March 2, 2025, and April 11, 2026. In response, SafePal fixed the vulnerability, strengthened system protections, reduced data retention in the affected system to 90 days, notified logistics partners, initiated a full order system audit with an independent security firm, and is continuing its investigation with external experts.

QHow does the article's 'AI Opinion' section contextualize the SafePal incident within the hardware wallet industry?

AThe 'AI Opinion' notes this is the third such leak of customer contact data from hardware wallet companies in recent years, following similar incidents at Ledger (2020) and Trezor. It highlights a pattern where attackers use the data for phishing campaigns impersonating support. It also points out that the vulnerability was not in the cryptographic security of the hardware wallet itself, but in a third-party web service plugin, suggesting auxiliary systems are a weak link.

你可能也喜歡

V神提议让以太坊借鉴比特币模式。原因为何

以太坊联合创始人维塔利克·布特林近期再次公开认可比特币基础技术的优势,并指出其UTXO(未花费交易输出)模型可作为扩展以太坊规模的一种途径。他强调,以太坊的未来并非简单复制单一架构,而是融合多种设计,在保持网络开放与安全的同时提升吞吐能力。 这是布特林近年来至少第二次公开谈论借鉴比特币长处。此前他曾赞赏比特币协议的简洁优美。然而在2021年,他曾批评比特币技术效率低下,并认为以太坊市值可能超越比特币。但自那时起至2026年8月,ETH对比特币的价格已下跌近65%。 布特林表示,比特币社区因率先提出许多理念而值得感谢,这些理念或将被引入以太坊。他指出,UTXO模型能帮助以太坊在不大幅牺牲去中心化的情况下进行扩容。 多年来,比特币因其固定的发行上限、缺乏内置收益机制以及常被诟病的速度慢、成本高等问题而受到批评,其去中心化治理模式也曾被视为发展的障碍。基于这些观点,大量替代加密货币项目涌现,并常以“比特币杀手”自居。但近年來,主要区块链项目在技术和经济模型上开始趋向于比特币的基本原则。 在扩展计划方面,布特林引用研究指出,采用UTXO模型可解决以太坊状态数据快速增长的问题(目前每年约增100GB)。若维持现状,运行全节点将过于昂贵,从而威胁网络的去中心化和抗审查性。以太坊基金会研究员托尼·瓦斯塔特于2026年7月提出引入原生UTXO支付,该方案无需永久存储智能合约数据,仅需记录代币是否花费。预估效果显示:对于10亿条记录,现有账户模型需占用100-150GB,而UTXO方案仅需约300MB,缩减幅度达99.8%。最终方案将采用混合架构,在账户上保留智能合约,同时汲取两种模型的优势。

cryptonews.ru剛剛

V神提议让以太坊借鉴比特币模式。原因为何

cryptonews.ru剛剛

比特币在63,500美元附近横盘整理,预示上下波动可能性

比特币价格近期在63,500美元附近横盘震荡,未能突破64,000美元阻力位,但保持在60,000美元支撑位之上。分析师指出,资金流向已发生变化:五月以来美国现货ETF持续净流入,第三季度净买入约11,000 BTC,与第二季度末的大幅资金流出形成对比,显示机构卖压已转为买盘。 市场数据显示,现货交易量降至两年低点,永续合约量达三年低位,波动性也接近多年最低水平。这种在市场极度清淡时出现需求,常是形成稳固底部的信号。专家将比特币过去六个月在60,000至80,000美元区间的盘整解读为“夏季惰性”,但链上数据已开始显现市场情绪从恐慌转向谨慎的筑底迹象。 当前市场风险双向存在。比特币被困在62,000至64,000美元的窄幅区间内,高杠杆率加剧了风险。永续合约未平仓头寸维持在高于平均的300,000 BTC以上,而交易量锐减,使得市场在任一方向都容易因清算引发剧烈波动。 根据HCN AI分析师的当前预测(价格63,338美元),展望为中性。基准情景(概率47%)看跌至62,249美元;看跌情景(概率32%)目标60,982美元;看涨情景(概率21%)目标64,098美元。加权预期与基准情景一致,约为下跌1.7%,且下行风险的幅度和概率均高于上行潜力。技术分析和动量指标偏弱,市场主要依靠资金流入支撑。本周关键区间狭窄(约4.9%):若突破64,098美元将扭转势头,若跌破62,249美元则可能下探60,982美元。

cryptonews.ru1 分鐘前

比特币在63,500美元附近横盘整理,预示上下波动可能性

cryptonews.ru1 分鐘前

交易

現貨

熱門文章

如何購買DATA

歡迎來到HTX.com!在這裡,購買DATA Network (DATA)變得簡單而便捷。跟隨我們的逐步指南,放心開始您的加密貨幣之旅。第一步:創建您的HTX帳戶使用您的 Email、手機號碼在HTX註冊一個免費帳戶。體驗無憂的註冊過程並解鎖所有平台功能。立即註冊第二步:前往買幣頁面,選擇您的支付方式信用卡/金融卡購買:使用您的Visa或Mastercard即時購買DATA Network (DATA)。餘額購買:使用您HTX帳戶餘額中的資金進行無縫交易。第三方購買:探索諸如Google Pay或Apple Pay等流行支付方式以增加便利性。C2C購買:在HTX平台上直接與其他用戶交易。HTX 場外交易 (OTC) 購買:為大量交易者提供個性化服務和競爭性匯率。第三步:存儲您的DATA Network (DATA)購買DATA Network (DATA)後,將其存儲在您的HTX帳戶中。您也可以透過區塊鏈轉帳將其發送到其他地址或者用於交易其他加密貨幣。第四步:交易DATA Network (DATA)在HTX的現貨市場輕鬆交易DATA Network (DATA)。前往您的帳戶,選擇交易對,執行交易,並即時監控。HTX為初學者和經驗豐富的交易者提供了友好的用戶體驗。

755 人學過發佈於 2026.07.01更新於 2026.07.01

如何購買DATA

相關討論

歡迎來到 HTX 社群。在這裡,您可以了解最新的平台發展動態並獲得專業的市場意見。 以下是用戶對 DATA (DATA)幣價的意見。

活动图片